PT-2001-1567 · Microsoft · Sql Server
Published
2001-07-21
·
Updated
2018-10-12
·
CVE-2001-0344
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server versions 7.0 and 2000 Gold
Description
A security issue in Microsoft SQL Server allows local database users to elevate their privileges. This is achieved by reusing a cached connection of the sa administrator account through an SQL query method in Mixed Mode.
Recommendations
For Microsoft SQL Server version 7.0, consider restricting access to the sa administrator account to prevent privilege escalation.
For Microsoft SQL Server 2000 Gold, restrict the use of Mixed Mode to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sql Server